• Home
  • Reviews
  • Featured
  • Archives
  • Videos
  • Devices
  • Tegra
  • Send Tips
  • Contact
  • AndroidCommunity on Twitter AndroidCommunity on Facebook AndroidCommunity on Google+ AndroidCommunity RSS Feed

Android Community

    • MUST READ

      STORIES

    • Android 4.3 leaks on video with new camera UI

      May 24, 2013

    • HTC One ‘Senseless Edition’ could arrive this summer

      May 23, 2013

    • Verizon HTC One reality returns as DROID DNA offer pops up

      May 20, 2013

  • Trending Topics
  • Jelly Bean
  • NVIDIA
  • Galaxy S 4
  • HTC One
  • Nexus 7
  • Sell Your Used Phone

Google fills Android Market XSS hole

4
  • By Shane McGlaun
  • on 8 Mar, 2011

Google fills Android Market XSS hole

Google has filled a security hole in the Android Market that would allow the installation of apps onto a user’s device without the user’s consent to the install. The hole even allowed the installation of an app on the user device without having physical access to the Android smartphone or tablet. The hole was in the cross-site scripting or XSS on the Android Market.

The persistent XSS vulnerability was in the description fields for apps on the Android Market web store. The field allows nefarious types to inject JavaScript code that was executed when the page was accessed on the browser. The malicious code could be triggered remotely to install a malicious app.

The only caveat to exploit the hole was that the user had to be logged into the web store. The exploit was brought to the attention of Google by John Oberheide, a security specialist for Android devices.

[via H-online

Share
  • Verizon HTC One "will be announced later"
  • New Nexus 7 reportedly shipping now, launching next month
  • HTC One with a larger 5-inch display coming soon

Tags: Android SecurityAndroid-Markethack

  • http://pulse.yahoo.com/_OBHHAMY4CMNNXHQAQK55GGDUE4 Asdjikj Kjskaj

    nice work google.

    http://tiny.cc/t5ylh

  • http://pulse.yahoo.com/_OBHHAMY4CMNNXHQAQK55GGDUE4 Asdjikj Kjskaj

    nice work google.

    http://tiny.cc/t5ylh

  • http://pulse.yahoo.com/_OBHHAMY4CMNNXHQAQK55GGDUE4 Asdjikj Kjskaj

    nice work google.

    http://tiny.cc/t5ylh

  • Annoyed

    It mentions someone who is a ‘security specialist’ for Android devices. If he is employed at Google he should try finding the rest of the holes. If not, then fuck him just kidding

  • Search

  • REVIEWS

    • AT&T LG Optimus G Pro ReviewAT&T LG Optimus G Pro Review
    • Iron Man 3 game Review: what you need to knowIron Man 3 game Review: what you need to know
    • Samsung GALAXY S 4 ReviewSamsung GALAXY S 4 Review
    • Samsung Galaxy Note 8.0 ReviewSamsung Galaxy Note 8.0 Review
    • Pebble review: Two weeks with a smartwatchPebble review: Two weeks with a smartwatch
  • HANDS-ON & QUICK LOOKS

    • Coolpad Quattro II 4G and 8920 hands-onCoolpad Quattro II 4G and 8920 hands-on
    • Kyocera Hydro XTRM and EDGE hands-onKyocera Hydro XTRM and EDGE hands-on
    • Opera for Android exits beta, we go hands onOpera for Android exits beta, we go hands on


  • T-Mobile G1 Accessories
  • RECENT COMMENTS

  • About
  • Contact
  • Terms of Use
  • Privacy Policy
  • Advertise

Copyright 2013 Android Community